The railroad is not the rails. Rails move nothing.
For a year and a half, the entire payments world has been building agentic commerce: protocols, wallets, checkouts. Almost everything is built — almost nothing is moving. Because a railroad is also a timetable, a ticket, and liability for the baggage. Markets are launched not by those who build the tech, but by those who take on the risk.
The whole payments world is building. Nobody is riding.
The race started quietly. In November 2024, Stripe shipped tools that let an AI agent issue itself a single-use virtual card and pay with it (Stripe agent toolkit, Stripe blog announcement, November 2024). At the time it looked like a developer utility. Nobody said the word "revolution."
Six months later, quiet was over. Visa and Mastercard unveiled their agentic payment programs in the same April of 2025, one day apart: Mastercard Agent Pay on April 29, Visa Intelligent Commerce on April 30 (press releases from both companies). When two competitors who split the world's card market run in the same direction a day apart, that is not an experiment. That is consensus.
From there the pace only climbed. In September 2025, Google gathered more than sixty organizations around AP2, its standard for agentic payments (Google announcement, September 16, 2025). And by August 2026, Cloudflare was already handing out wallets to agents — it opened name reservations (Cloudflare Wallets, August 4, 2026). Between those points: five more events, including one loud shutdown. The full chronology is on the band below.
Five protocols. Forty corporations. A year and a half.
Now the numbers from the other side. Merchants in the UK and the US put the share of transactions that involve AI at all at roughly three percent (Checkout.com, UK/US merchant survey, June 2026). In almost every one of those cases, a human still presses the final button. Forrester, in mid-2026, says it plainly: people have learned to search for products through AI, but the decision and the payment stay human almost every time. And purchases where an agent decided and paid on its own? Statistically zero.
Here is the most interesting part: a real agentic checkout already exists. At Google. You press "Buy" in AI Mode or Gemini, review the final price and the address, confirm the payment — and only then does the machine step in: Google's AI agent walks through checkout on the merchant's site with your card from Google Wallet (Google's help pages for shopping in AI Mode, support.google.com, 2026). The last button belongs to the human. The checkout belongs to the agent. This is not a concept and not a demo. This is production.
It just looks like this, for now. It works with selected merchants only. Only in the US and Australia. If the price has shifted or the item sold out, the purchase silently dies. Some stores make you link an account first. Alcohol and digital goods — out. And to any "something went wrong," Google gives one answer: contact the merchant.
The rails are laid. The locomotive is out of the shed. There are no passengers.
Everything is built — nothing is moving.
Not early, not a bubble, not a standards war.
There are two ready-made explanations for a gap like this, and neither survives contact with the facts.
First: "it's just early." Young technology, the market will ripen, wait. This explanation has one problem: the market leader already tried — and retreated. OpenAI opened a store inside ChatGPT in September 2025. Five months later it closed it. Out of millions of Shopify stores, roughly a dozen had connected to the checkout (Shopify president Harley Finkelstein, March 2026). Walmart measured it: completing a purchase inside a chat happens three times less often than after a hop to the website (Walmart, March 2026). "Early" is when nobody has tried yet. Here they tried. And rolled it back.
Second: "it's a bubble." Hype inflated by announcements, hollow inside. But a bubble doesn't explain why Visa, Mastercard, American Express, Stripe, Google, Amazon and Shopify — forty organizations — actually sat down at one Linux Foundation table and handed over a protocol (x402 Foundation, July 2026). And it doesn't explain Google's live checkout: bubbles don't ship code to production.
There is a third answer, a subtler one: "too many standards, the market is waiting for a winner." Sounds smart. But the protocols are already stacking into layers of one system rather than fighting each other: one handles the agent's identity, another its authority, a third the payment. Visa even built an adapter that accepts agents of any standard (Visa, April 2026).
Not early. Not hollow. Not a standards muddle.
The reason lies elsewhere. To see it, step back thirty years — to the most famous button in the history of commerce.
The button had something to stand on.
Millions of people will press it today. Almost none of them know it has an author.
Amazon switched on "Buy Now with 1-Click" in September 1997 (Amazon press release, September 1997). More than that — the button was patented: US patent 5,960,411, granted in 1999, with Bezos himself among the inventors. Amazon immediately used the patent as a weapon: in October 1999 it sued Barnes & Noble, and the court shut down their one-click checkout. Apple chose not to fight and licensed the button for iTunes in 2000 (the deal is public, its terms were never disclosed). For eighteen years, until the patent expired in 2017, "one click" belonged to one company.
The button is remembered as a triumph of convenience: remove the friction and people will buy. Agentic commerce lives on exactly that faith today: we are removing friction again — so they will buy again.
But look at what the button was standing on.
The habit of buying online did not exist in 1997: roughly 18% of American households had internet access (US Census Bureau, October 1997). The button ran on different fuel — a loyal core: repeat customers placed 58% of Amazon's orders that year (Bezos's 1997 letter to shareholders). And beneath all of it lay an insurance policy twenty-three years older than the button: the right to dispute a charge and get your money back, granted to American buyers by the Fair Credit Billing Act back in 1974.
The layers stack in strict order. At the bottom, protection: whatever happens, the money comes back. On top of it, the trust of people who had already bought. And only above that, convenience: it removes the last friction and then spins the habit up on its own. The button did not create trust. The button cashed it out.
Convenience is the last layer, not the first.
Measure the buildout in other people's yeses.
The button's history suggests how to read today's construction site. Not by announcement dates — by the number of other people's yeses a layer needs before it works.
A protocol needs zero. You write the spec yourself. You build the agent's wallet yourself. You stand up the developer sandbox yourself. Coinbase and Cloudflare asked no banks and no stores when they published x402: the code went up — and the protocol existed (May 2025). That is why this part is finished in full: everything that can be built alone has been built.
The merchant's upside needs one yes. And nobody has gotten it. OpenAI's offer to the merchant ran like this: install our checkout, pay the commission, and keep the returns and the disputes. The merchant did the math — and didn't come. That dozen stores out of millions is the price of a two-party deal that never closed.
The rule for "who pays when the agent is wrong" needs everyone's yes at once: card networks, banks, platforms, merchants, regulators. That table hasn't even been set. Not because they don't see the question — they all see it. It's that every answer costs money to whoever says it out loud. The bank nods at the platform. The platform writes in its terms: disputes go to the merchant. The merchant shuts the door. The circle closes.
Zero yeses — built. One yes — stalling. Everyone's yes — not started.
The engineers finished first not because they ran faster. Their stretch is simply the only one where there is no one to negotiate with.
The code is finished. The negotiations have barely begun.
The planet's biggest merchant is suing an agent.
Here is the heart of the story. The heaviest door is held not by the buyer, not by the bank, not by the regulator — by the merchant. And before you file him under "luddite," look at how the biggest merchant on the planet behaves.
Amazon is building agentic commerce itself — and at the same time fighting someone else's agent at its own door. In November 2025 the company sued Perplexity: its agent Comet was logging into customers' accounts and placing orders for them while — by Amazon's account — disguising itself as an ordinary browser. In March 2026 a court barred the agent. And on August 4, 2026, an appeals court lifted the ban — with wording that will enter the textbooks: under the law, it is not the agent's developer who visits the site but the user whose intent the agent carries out (US Ninth Circuit decision, August 4, 2026). Amazon lost the round. But nine months of litigation for the right to keep an agent out — that is the price of the question, not a whim.
Why hold the door at all? Because a merchant's storefront is not a shelf of goods. It is a machine he has spent years tuning for a live human. Recommendations. "Frequently bought together." The deal at the register. The email chasing the abandoned cart. Every detail exists for one purpose: so that a person who came for one item leaves with three.
The agent arrives with a list. It doesn't see the banner, doesn't respond to "today only," doesn't mourn the abandoned cart. The persuasion techniques that e-commerce stands on simply don't fire on agents (Harvard Business Review, May 2026). The agent takes exactly one item and leaves. The average basket shrinks by construction — even when the order goes through.
Now add up the merchant's economics. Letting the agent in means switching off the upsell machine and trading from a bare list. On top of that, the platform's commission: for Shopify merchants, checkout in ChatGPT cost four percent of every purchase (Shopify merchant onboarding terms for Instant Checkout, January 2026). A smaller basket, minus the commission — and all of that discount buys entry into a channel where buyers are still a fraction of a percent.
The merchant didn't fall behind the future. He did the math on it.
By default, the agent's mistake is the merchant's bill.
The locked door has a second reason, heavier than the first. It is written in the fine print.
Read any agentic checkout's terms down to the "returns and disputes" section. Instant Checkout's rules left them with the merchant, in plain text (OpenAI's Agentic Commerce Protocol specification, September 2025). The platform's agent ran the purchase — and the dispute lands on the store. The risk didn't vanish and wasn't shared. It was dumped on one party by default — the very party being begged to open the door.
It gets worse. The whole edifice of buyer protection rests on one question: "did you authorize this charge?" For half a century it worked, because a stranger's hand in your wallet is easy to see. With an agent, the question breaks: formally, everything was authorized — you handed it the card yourself. The new dispute sounds different: "I authorized, but not this." No card network, no bank, no platform has rules for that dispute.
The market has measured this hole itself — four times in half a year. The Payments Association handed a hundred finance and risk executives in UK retail a simple case: an agent spends £2,000, the buyer says "that's not what I meant" — who pays? The answers split: 24% said "it depends," 21% said split it, 18% said the AI vendor pays; only 41% trust the current rules at all (The Payments Association, UK, Q1 2026). The professionals of risk cannot agree on who pays. That is the answer.
Merchants say the same thing in the open: nearly two-thirds of those already testing agentic protocols demand a liability framework urgently (PayPal Agentic Commerce Pulse, survey of 498 US merchants, February–March 2026; 414 respondents were asked this question).
Now pull both reasons into one point — the merchant did, long ago. Letting the agent in means earning less: the upsell machine doesn't work on it, the basket shrinks, the commission sits on top. And with the same motion, answering for more: every mistake the agent makes lands on the store by default. Less revenue, more risk. That is not two problems — that is one deal, and it is a bad one. The door will open not when the protocols improve, but when the deal is rewritten: stop cutting the revenue, and move the risk to someone built to carry it.
The merchant isn't holding the door out of fear. He has read the terms of the deal.
The buyer trusts the agent with the head, but not the hand.
One side of the deal remains — the one all of this was built for.
Something strange has happened to the buyer. He has already trusted the agent with his head — and not with his hand. Two-thirds of Americans are ready to let AI compare prices, but only 14% would trust it to place the order (YouGov, survey of 1,287 US adults, December 2025; the British version of the same survey repeats it almost word for word: 66% and 11%). Advise me all you want. The button is mine.
14% would trust the agent with the button. The click never comes.
This is not a whim and not force of habit. Ask the buyer what he is missing before he lets go of the hand — he names three things: a spending cap, instant revocation of permission, easy cancellation of a purchase (Checkout.com, consumer survey across six markets, June 2026). Read that list again. There is not a word in it about convenience, speed or price. All three items are about one and the same moment: what happens when it goes wrong.
And the agent will be judged more harshly than a human. A cashier's mistake gets forgiven: apologize, void it, ring it up again. The agent gets forgiven nothing: 60% of Britons would drop an AI assistant after one single shopping mistake (YouGov for ACI Worldwide, survey of 2,080 adults, June 2026). One slip — and that buyer is gone.
So the buyer, it turns out, is asking for the same thing as the merchant. Not faith in the technology — boundaries, revocation, a way to unwind mistakes. Both sides of the register, without conspiring, have named the same launch condition.
The buyer trusts the agent with the head. Not with the hand.
Rails don't move markets. Converging conditions do.
So the picture is assembled: the rails are laid, the merchant has locked the door, the buyer keeps a finger on the button. What now? What news would mean the train has actually moved?
Payments history has answered this question before — with contactless cards. The technology itself is not new: the first mass contactless cards were carrying passengers on Seoul buses back in 1995 (the Upass transit card, Seoul). In October 2015, US card networks shifted fraud losses onto whoever hadn't upgraded their terminals (the EMV liability shift, Visa and Mastercard rules, October 2015) — and stores installed new hardware almost everywhere. The infrastructure was in place. And nobody started paying contactless: three years later it still accounted for less than one card purchase in a hundred (contactless share in the US as of 2018 — under 1%, industry estimates from Visa and A.T. Kearney).
The takeoff came when two more conditions joined the ready terminals: banks began mass-issuing cards with the contactless chip (Chase and the other largest US banks, 2018–2019), and COVID made touching a stranger's terminal unappealing (2020). Three conditions converged — and a way to pay that had been an exotic for a quarter century became the norm within a couple of years.
The lesson is unpleasant for builders: finished infrastructure can stand idle for years. Rails move nothing. Converging conditions move everything.
So — don't watch the announcements. Protocols will keep shipping, each will be called a breakthrough, and none will move anything: everything that can be built alone has already been built. The news that actually sounds the whistle reads differently: a major player says, in public — "the agent's mistakes are on us." Here is the cap, here is the process, the money comes back. In 2015 the market was moved not by a new chip but by a transfer of losses. It will be the same here.
The whistle is not a protocol announcement. The whistle is the first signature under someone else's mistake.
The railroad is not the rails.
Now the thesis assembles itself.
The railroad is not the rails. Rails are the necessary, smaller part of it. A railroad starts to carry when everything else appears on top of the iron: the timetable, the ticket, the rules of carriage — and the liability for the baggage, written into that ticket. Remove it, and the mightiest locomotive remains an exhibition piece.
Agentic commerce laid its rails in a year and a half — faster than its own builders expected. Protocols, wallets, a live checkout: everything that can be done alone is done. What comes next cannot be written in code: a deal that makes opening the door worth the merchant's while; boundaries that let the buyer release the button; and a rule for "who pays for the mistake" with someone's signature under it. It has gone this way twice already: the button of 1997 stood on a money-back right from 1974; contactless took off after the loss transfer of 2015. Each time, the technology was launched not by an engineer. It was launched by whoever took on the risk.
Markets are not launched by those who lay the rails. Markets are launched by those who take on the risk.
Human Beyond builds the path from intention to autonomous action — everything that lies between "I want" and "done": boundaries, permissions, execution, control, the unwinding of mistakes. Not a guarantee for other people's purchases — the controllability that makes a launch possible at all: an agent whose limits can be drawn, whose run can be stopped halfway, whose mistake can be taken apart, is the only agent that will ever be trusted with the button.
The rails are laid. The whistle has not sounded. Until it does, every new announcement deserves one question — not "what did you build," but "whose mistake are you willing to pay for."
Key takeaways
- In a year and a half (November 2024 — August 2026) the payments giants built the machinery of agentic commerce — five protocols, agent wallets, a live Google checkout — yet purchases where an agent decides and pays on its own are statistically zero: UK/US merchants put AI-involved transactions at roughly 3%, and a human still presses the final button.
- The lesson of the 1-Click button (1997): convenience is the last layer, not the first. Amazon's button stood on a money-back right (the Fair Credit Billing Act of 1974) and a loyal core of buyers (58% repeat orders) — it did not create trust, it cashed trust out.
- Measure the buildout by the number of outside yeses a layer needs: a protocol is built alone — and is finished; the merchant's upside needs a two-party deal — and is stalling (a dozen stores out of millions joined Instant Checkout); the rule for who pays for an agent's mistake needs everyone's consent — and has not been started.
- The merchant holds the door for rational reasons: an agent ignores the upsell machine (the average basket shrinks by construction), a 4% platform commission sits on top, and platform terms leave returns and disputes with the store by default. Less revenue plus more risk is simply a bad deal.
- The market will be launched not by another protocol but by the first major player to publicly take on the losses from agent mistakes — the way the EMV liability shift of 2015 launched contactless payments.
FAQ
- Why has agentic commerce not taken off yet?
- The technology is not the bottleneck — protocols, wallets and checkouts are built. What is missing is the institutional layer: platform terms dump returns and disputes on the merchant by default, buyers refuse to hand over the final button without spending caps and instant revocation, and the rule for who pays when an agent makes a mistake requires card networks, banks, platforms, merchants and regulators to agree at once — and nobody has taken that risk on. Markets are launched by whoever takes on the risk, not by whoever ships the tech.
- Can AI agents already buy things on their own?
- Almost never. UK and US merchants put the share of transactions with any AI involvement at roughly 3% (Checkout.com, June 2026), and the decision and payment stay human almost every time. The only working agentic checkout runs at Google, for selected merchants in the US and Australia: the human confirms the final price, address and payment, and only then does Google's agent execute the checkout on the merchant's site. Fully autonomous purchases — where the agent decides and pays — are statistically zero.
- What will signal that agentic commerce is actually launching?
- Not another protocol announcement. The signal is the first public transfer of risk: a major player stating "the agent's mistakes are on us," with spending caps, a dispute process and refunds attached. That is how contactless payments took off — terminals stood ready for years, and the market moved after the EMV liability shift of 2015 rearranged who paid for fraud, followed by mass card issuance and COVID.